CVE List

Id CVE No. Status Description Phase Votes Comments Actions
305  CVE-1999-0306  Candidate  buffer overflow in HP xlock program.  Proposed (19990714)  ACCEPT(3) Baker, Frech, Northcutt | MODIFY(1) Prosser | NOOP(1) Shostack | REJECT(1) Christey  Prosser> This is another of those with multiple affected OSs. | Refs: CA-97.13, http://207.237.120.45/linux/xlock-exploit.txt, | HPSBUX9711-073, SGI 19970502-02-PX, Sun Bulletin 000150 | Christey> XF:hp-xlock points to SGI:19970502-02-PX which says this is | the same problem as in CERT:CA-97.13, which is CVE-1999-0038.  View
4737  CVE-2002-0345  Candidate  Symantec Ghost 7.0 stores usernames and passwords in plaintext in the NGServerparams registry key, which could allow an attacker to gain privileges.  Proposed (20020502)  ACCEPT(2) Frech, Prosser | NOOP(4) Cole, Cox, Foat, Wall  Prosser> This was verified and responded to via BugTraq and fixed via | LiveUpdate http://online.securityfocus.com/archive/1/259559  View
2922  CVE-2001-0101  Candidate  Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.  Modified (20020222-01)  ACCEPT(4) Baker, Cole, Prosser, Ziese | MODIFY(1) Frech | NOOP(1) Wall  Prosser> TURBO:TLSA2000024-1 | http://www.turbolinux.com/pipermail/tl-security-announce/2000-December/000027.html | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:fetchmail-authenticate-gssapi(7455)  View
2508  CVE-2000-0939  Candidate  Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows remote attackers to cause a denial of service by repeatedly submitting a nonstandard URL in the GET HTTP request and forcing it to restart.  Proposed (20001129)  ACCEPT(2) Frech, Mell | NOOP(1) Cole | REJECT(1) Renaud  Renaud> SWAT makes this DoS easier to perform, but actually, it is an inetd | problem, not a swat problem.  View
286  CVE-1999-0287  Candidate  Vulnerability in the Wguest CGI program.  Proposed (19990714)  MODIFY(2) Frech, Shostack | NOOP(4) Blake, Levy, Northcutt, Wall | REJECT(2) Baker, Christey  Shostack> allows file reading | Frech> XF:http-cgi-webcom-guestbook | Christey> CVE-1999-0287 is probably a duplicate of CVE-1999-0467. In | NTBUGTRAQ:19990409 Webcom"s CGI Guestbook for Win32 web servers | Mnemonix says that he had previously reported on a similar | problem. Let"s refer to the NTBugtraq posting as | CVE-1999-0467. We will refer to the "previous report" as | CVE-1999-0287, which could be found at: | http://oliver.efri.hr/~crv/security/bugs/NT/httpd41.html | | 0287 describes an exploit via the "template" hidden variable. | The exploit describes manually editing the HTML form to | change the filename to read from the template variable. | | The exploit as described in 0467 encodes the template variable | directly into the URL. However, hidden variables are also | encoded into the URL, which would have looked the same to | the web server regardless of the exploit. Therefore 0287 | and 0467 are the same. | Christey> BID:2024  View

Page 20927 of 20943, showing 5 records out of 104715 total, starting on record 104631, ending on 104635

Actions